My fear is that even allocating subdomains of opam.ocaml.org is a tough problem in the real world. And you're not only doing (the equivalent of) that, you're also running an alternative CA, with alternative signing software. I wish you success, but this seems ambitious.
In contrast, we know the CA/https system works and we know its failings (in particular the evil CA attacks, mostly fixed by pinning). That system is highly distributed and needs no custom software. It also needs little extra work, which is always a good thing.
I've looked at the TUF papers. Can you elaborate on the attack you're describing? They don't seem to compare TUF to alternatives (that I could find). (Edit: and to be clear, my straw-man here is serving the initial git revision information over HTTPS, fetching the hashed data over HTTP & mirrors, and then verifying the hash)